Bug #70860 [Opn->Csd]: Broken pointer in the memory heap.

From: Date: Fri, 06 Nov 2015 08:41:46 +0000
Subject: Bug #70860 [Opn->Csd]: Broken pointer in the memory heap.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197073@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70860&edit=1

 ID:                 70860
 Updated by:         laruence@php.net
 Reported by:        a dot cobest at gmail dot com
 Summary:            Broken pointer in the memory heap.
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   any
 PHP Version:        7.0.0RC6
-Assigned To:        
+Assigned To:        laruence
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2015-11-05 17:52:45] a dot cobest at gmail dot com

Thank you, it's works. It is what we need!

------------------------------------------------------------------------
[2015-11-05 14:30:25] nikic@php.net

If you want to debug memory management issues run USE_ZEND_ALLOC=0 valgrind php. The ZMM only helps
you with memory leaks, not with other kinds of memory problems.

------------------------------------------------------------------------
[2015-11-05 12:19:58] a dot cobest at gmail dot com

Typo in test:
---------------
PHP_FUNCTION(double_free) {
    char * tmp = emalloc(sizeof(char)*7);
    memcpy(tmp, "alloc1", sizeof("alloc1"));
    efree(tmp);
    efree(tmp);
    char * tmp1 = emalloc(sizeof(char)*4);
    memcpy(tmp1, "all2", sizeof("all2"));
    char * tmp2 = emalloc(sizeof(char)*4);
    memcpy(tmp2, "all3", sizeof("all3")); // tmp1 has string "all3"
}

------------------------------------------------------------------------
[2015-11-05 12:07:02] a dot cobest at gmail dot com

typo

------------------------------------------------------------------------
[2015-11-05 12:06:06] a dot cobest at gmail dot com

Description:
------------
Short description: Broken pointer may appear due to the fact that there is no checking that the
memory has been "freed".
Long description: Rewriting the extension to php7 often get a Segmentation fault. it turned out that
if somewhere I release the memory I get SIGSEGV in an unexpected place. 
The memory manager does not have a check that the memory has already been freed earlier (example
attached). This problem will produce strange and hard-to-diagnose bugs

Like this (also like this https://bugs.php.net/bug.php?id=70249 or this https://bugs.php.net/bug.php?id=70033 or this https://bugs.php.net/bug.php?id=70017 etc):

php -v:
PHP 7.0.0RC6 (cli) (built: Nov  2 2015 10:24:35) ( NTS DEBUG )
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies

uname -a:
Darwin shadow 14.5.0 Darwin Kernel Version 14.5.0: Wed Jul 29 02:26:53 PDT 2015;
root:xnu-2782.40.9~1/RELEASE_X86_64 x86_64

OS:
MacOS 10.10.5

gdb backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8,
__zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
1291			heap->free_slot[bin_num] = p->next_free_slot;

Thread 1 (Thread 0xf03 of process 97454):
#0  0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8,
__zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
#1  0x00000001003ca38e in zend_mm_alloc_heap (heap=0x101200040, size=72, __zend_filename=0x10090b633
"Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0)
at Zend/zend_alloc.c:1358
#2  0x00000001003cb4bf in _emalloc (size=40, __zend_filename=0x10090b633
"Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0)
at Zend/zend_alloc.c:2442
#3  0x00000001004282ca in zend_string_alloc (len=8, persistent=0) at Zend/zend_string.h:121
#4  0x0000000100421b5f in zend_string_init (str=0x1008d2b73 "function", len=8,
persistent=0) at Zend/zend_string.h:157
#5  0x0000000100421c8f in _zend_hash_str_update (ht=0x102beb120, str=0x1008d2b73
"function", len=8, pData=0x7fff5fbfdd68, __zend_filename=0x10090ed84
"Zend/zend_hash.h", __zend_lineno=393) at Zend/zend_hash.c:598
#6  0x0000000100410db0 in zend_symtable_str_update (ht=0x102beb120, str=0x1008d2b73
"function", len=8, pData=0x7fff5fbfdd68) at Zend/zend_hash.h:393
#7  0x0000000100410ff3 in add_assoc_str_ex (arg=0x7fff5fbfdea0, key=0x1008d2b73
"function", key_len=8, str=0x102b748c0) at Zend/zend_API.c:1361
#8  0x000000010042a211 in zend_fetch_debug_backtrace (return_value=0x7fff5fbfdf58, skip_last=0,
options=0, limit=0) at Zend/zend_builtin_functions.c:2595
#9  0x0000000100442da6 in zend_default_exception_new_ex (class_type=0x103805db8, skip_top_traces=0)
at Zend/zend_exceptions.c:201
#10 0x0000000100441af7 in zend_default_exception_new (class_type=0x103805db8) at
Zend/zend_exceptions.c:224
#11 0x0000000100410c13 in _object_and_properties_init (arg=0x7fff5fbfe098, class_type=0x103805db8,
properties=0x0, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356)
at Zend/zend_API.c:1288
#12 0x0000000100410c76 in _object_init_ex (arg=0x7fff5fbfe098, class_type=0x103805db8,
__zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at
Zend/zend_API.c:1296
#13 0x000000010049dea1 in ZEND_NEW_SPEC_CONST_HANDLER (execute_data=0x10121c350) at
Zend/zend_vm_execute.h:3356
#14 0x00000001004712f4 in execute_ex (ex=0x10121bd00) at Zend/zend_vm_execute.h:417
#15 0x00000001003ed59e in zend_call_function (fci=0x7fff5fbfe3d0, fci_cache=0x7fff5fbfe3a8) at
Zend/zend_execute_API.c:854
#16 0x0000000100165bcb in zim_reflection_method_invokeArgs (execute_data=0x10121bc80,
return_value=0x10121b950) at ext/reflection/php_reflection.c:3370
#17 0x000000010049c267 in ZEND_DO_FCALL_SPEC_HANDLER (execute_data=0x10121b750) at
Zend/zend_vm_execute.h:842
#18 0x00000001004712f4 in execute_ex (ex=0x101217030) at Zend/zend_vm_execute.h:417
#19 0x0000000100471460 in zend_execute (op_array=0x101273300, return_value=0x0) at
Zend/zend_vm_execute.h:458
#20 0x000000010040b583 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
Zend/zend.c:1428
#21 0x000000010035abc6 in php_execute_script (primary_file=0x7fff5fbff308) at main/main.c:2471
#22 0x00000001005047b3 in do_cli (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:974
#23 0x00000001005035de in main (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:1345

Test script:
---------------
PHP_FUNCTION(double_free) {
    char * tmp = emalloc(sizeof(char)*7);
    memcpy(tmp, "alloc1", sizeof("alloc1")+1);
    efree(tmp);
    efree(tmp);
    char * tmp1 = emalloc(sizeof(char)*4);
    memcpy(tmp1, "all2", sizeof("all2")+1);
    char * tmp2 = emalloc(sizeof(char)*4);
    memcpy(tmp2, "all3", sizeof("all3")+1); // tmp1 has string "all3"
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70860&edit=1


Thread (6 messages)

« previous php.bugs (#197073) next »